XML-RPC Interface Vulnerability in WatchGuard Fireware
CVE-2017-14616
7.5HIGH
Summary
A Denial of Service vulnerability exists in WatchGuard Fireware prior to version 12.0, where an empty member element in an XML message sent to the XML-RPC interface can cause the wgagent to crash. This results in the immediate logout of any active users and disrupts the UI management of the device, making it impossible to manage the device effectively. Continuous failed login attempts exacerbate the issue, leading to a complete denial of access.
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved